Budibase · Vulnerability Disclosure

Budibase Vulnerability Disclosure

Vulnerability disclosure

Budibase publishes a vulnerability disclosure policy, but it lives only in the repository — not on the website, and not at /.well-known/security.txt on any host.

Budibase runs a coordinated vulnerability disclosure program on Hackerone.

AI AgentsAutomationInternal ToolsLow-CodeOpen-SourceWorkflow-Automation
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-04'
method: searched
source: https://github.com/Budibase/budibase/blob/master/SECURITY.md
description: >-
  Budibase publishes a vulnerability disclosure policy, but it lives only in the repository
  — not on the website, and not at /.well-known/security.txt on any host.
policy_published: true
policy_url: https://github.com/Budibase/budibase/blob/master/SECURITY.md
policy_text: >-
  "As an open source product, we will only patch the latest major version for security
  vulnerabilities. Previous versions of budibase will not be retroactively patched.
  Disclosing: Please report vulnerabilities via GitHub:
  https://github.com/Budibase/budibase/security/advisories/new"
intake:
  channel: GitHub Security Advisories
  url: https://github.com/Budibase/budibase/security/advisories/new
  status: 200
  verified: '2026-09-04'
  email: null
  note: >-
    Private vulnerability reporting through GitHub's advisory workflow — a coordinated
    disclosure channel, not a public issue tracker. No security@ email is published as an
    alternative, so a reporter without a GitHub account has no documented route.
supported_versions:
  policy: latest major only
  retroactive_patching: false
  note: >-
    Consequential for self-hosters: there is no long-term-support branch, so staying secure
    means staying current with a weekly release train.
bug_bounty:
  exists: false
  platforms_checked:
    - HackerOne
    - Bugcrowd
    - Intigriti
  result: No public bug bounty or VDP program found on any platform.
security_txt:
  served: false
  hosts_probed:
    - host: budibase.com
      status: 404
    - host: www.budibase.com
      status: 404
    - host: docs.budibase.com
      status: 404
    - host: budibase.app
      status: 403
    - host: account.budibase.app
      status: 403
  detail: >-
    An RFC 9116 /.well-known/security.txt pointing at the existing GitHub advisory intake
    would cost Budibase one static file and would make an already-real policy machine
    discoverable. It is the clearest single gap in this artifact.
safe_harbor:
  stated: false
disclosure_history:
  published_advisories: https://github.com/Budibase/budibase/security/advisories
  status: 200
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/budibase-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.